FDA Laws and Submission Guidance Catches up with Cyber Risks in Medical Devices

Posted on


The forgiveness period for medical device manufacturers not following the PATCH (Protecting and Transforming Cyber Healthcare) Act came to a close in October 2023. The Act, which became a law in late 2022 and went into effect in March 2023, is the first enforceable law focused specifically on cyber safety of medical devices. Joshua Corman likens it to “minimum seatbelt laws for medical devices” by requiring manufacturers to provide demonstrable proof of cybersecurity controls and visibility into their devices during pre-market FDA submission. 

Corman, who teaches secure development lifecycle and product security for Carnegie Mellon University’s grad school, is the founder of, a collection of thousands of volunteer experts from around the world with a common mission to improve cybersecurity in medical devices, transportation, and infrastructure systems, and the connected home. Josh was active in developing the PATCH Act, as well as the FDA’s latest pre-market cyber security guidance for device manufacturers that was published in September (2023).  

Now backed by law, the FDA’s guidance is no longer elective, and dictates how the agency evaluates medical devices going to market, says Corman, who also co-founded, where he’s demonstrated dozens of ways medical devices could be hacked to harm patients.

In this show, he talks about the nine-year journey to get medical device manufacturers to follow best practices and shift left in their DevOps practices, starting with secure by design and throughout the product lifecycle. And, since medical device software utilizes up to 90 percent of open-source components, SBOMs (software bill of materials) play a huge part in managing the risks associated with third-party code. 

While manufacturers initially pushed back on the cyber safety requirements, Corman notes that those who got on board with this guidance immediately began seeing benefits that made them more competitive, faster-to-market, and quicker to repair exploitable vulnerabilities found in their code.  


FDA Recommends Static Analysis for Medical Devices-CodeSecure Case Study

CDRH – FDA’s Center for Device and Radiological Health

CISA’s Known Exploited Vulnerabilities (CEV) Catalog  

Rugged Software Manifesto, co-written by Josh Corman

Book a Demo

We’re ready to help you integrate SAST and SCA security into your DevSecOps flow. Get a personally guided tour of our solution offerings to ensure you are receiving the right solution for your development team. 

book now